Category: OSINT

The Privacy, Security, & OSINT Show – Episode 121

EPISODE 121-This Week in Privacy & OSINT

This week I discuss my recent exposure using a credit card at a coffee shop, United Airlines' announcement to cover the cameras facing every passenger, another open database leak, the potential malware present on Dell computers, private baby names (seriously…), and five OSINT tips for online investigations.


SHOW NOTES:

INTRO:

Mark Z.

THIS WEEK IN PRIVACY:

Square Readers
https://www.forbes.com/sites/kateoflahertyuk/2019/04/30/data-of-80-million-americans-exposed-in-mystery-database-mega-leak
https://www.shodan.io/search?query=product%3Aelastic+port%3A9200+nal
https://d4stiny.github.io/Remote-Code-Execution-on-most-Dell-computers/
https://ppw.kuleuven.be/okp/_pdf/Laham2012TNPEW.pdf
https://www.emeraldinsight.com/doi/abs/10.1108/02683940810849648
https://www.aeaweb.org/articles?id=10.1257/0002828042002561

THIS WEEK IN OSINT:

https://emailrep.io/
https://leadferret.com/search
https://vincheck.info/free-license-plate-lookup/
https://www.vehiclehistory.com/license-plate-search/
https://inteltechniques.com/buscador/index.html

LISTENER QUESTIONS NEXT WEEK:

[email protected]


Data Removal Workbook:
https://inteltechniques.com/data/workbook.pdf

Affiliate Links:

PIA: https://privateinternetaccess.com/pages/buy-vpn/crimeinfo
ProtonVPN: https://protonvpn.net?aid=IntelTechniques
Amazon: http://amzn.to/2IAyNzm
Silent Pocket: https://silent-pocket.com/discount/IntelTechniques


 

The Privacy, Security, & OSINT Show – Episode 120

EPISODE 120-Private Purchase Failures

This week, I discuss recent privacy news, my failed attempt to buy anonymous iPhones, how prepaid credit cards can get us in trouble, and a new Instagram search tool that can help query bio information.


SHOW NOTES:

INTRO:

https://motherboard.vice.com/en_us/article/ywyz3x/hackers-could-read-your-hotmail-msn-outlook-microsoft-customer-support
https://www.nytimes.com/interactive/2019/opinion/internet-privacy-project.html
https://internethealthreport.org/2019/23-reasons-not-to-reveal-your-dna/
https://customercare.23andme.com/hc/en-us/articles/212170688-Requesting-account-closure
https://www.foxnews.com/tech/teens-1b-suit-claims-apples-facial-recognition-software-led-to-false-arrest

PRIVATE PURCHASE FAILURES:

https://www.apple.com/shop/product/MP7X2LL/A/iphone-se-128gb-space-gray-unlocked
https://mygift.giftcardmall.com/#transactions

OSINT:

https://www.searchmy.bio/search?q=gmail.com


Data Removal Workbook:
https://inteltechniques.com/data/workbook.pdf

Affiliate Links:

PIA: https://privateinternetaccess.com/pages/buy-vpn/crimeinfo
ProtonVPN: https://protonvpn.net?aid=IntelTechniques
Amazon: http://amzn.to/2IAyNzm
Silent Pocket: https://silent-pocket.com/discount/IntelTechniques


The Privacy, Security, & OSINT Show – Episode 119

EPISODE 119-How to Find Hidden Recording Devices

This week, my guest is Tom Gibbons, and he will explain the best ways to locate hidden recording devices such as microphones and cameras. Also, I have a slew of recent privacy news and a new OSINT tip to discuss.


SHOW NOTES:

INTRO:

Apple Update
https://www.forbes.com/sites/thomasbrewster/2019/04/10/what-happened-when-the-dea-demanded-passwords-from-lastpass/#10f93bdb7ebe
https://www.zdnet.com/article/cybercrime-market-selling-full-digital-fingerprints-of-over-60000-users/
https://www.bombitup.net/
https://www.foxnews.com/tech/thousands-of-amazon-workers-listening-to-alexa-recordings-hear-personal-information-even-potential-crimes-report
https://news.sky.com/story/family-discovers-hidden-camera-livestreaming-in-airbnb-11684049

HOW TO FIND HIDDEN RECORDING DEVICES:

Tom Gibbons
http://www.tscmnet.com/

Thermal Imaging Camera: https://amzn.to/2UJF70w

Network Scanning Apps:

https://itunes.apple.com/us/app/blue-hound/id1067368392?mt=8

https://play.google.com/store/apps/details?id=com.overlook.android.fing&hl=en_US

OSINT:

https://www.carvana.com/trades/new?licenseplate=HACKER&state=CA


Data Removal Workbook:
https://inteltechniques.com/data/workbook.pdf

Affiliate Links:

PIA: https://privateinternetaccess.com/pages/buy-vpn/crimeinfo
ProtonVPN: https://protonvpn.net?aid=IntelTechniques
Amazon: http://amzn.to/2IAyNzm
Silent Pocket: https://silent-pocket.com/discount/IntelTechniques


New Online Investigation (OSINT) Resources

It has been a while since I posted a collection of new OSINT resources, so this one is lengthy. The following were recently added to the online search tools, live training curriculum, and online training courses.

Trumail API (https://api.trumail.io/v2/lookups/[email protected]): This API was demonstrated in my recent webinar about email search. It serves as a verification option to identify legitimate email addresses and filter burner accounts. It also explicitly identifies disposable and free email services, while announcing whether an account is a catch-all.

Spycloud (https://portal.spycloud.com/endpoint/enriched-stats/[email protected]): This API provides a positive or negative indicator for an email address present in the Spycloud collection of data breaches. While the information is minimal, no API key is required. It also identifies the number of breached email records for the domain.

 

VIN-NHTSA (https://vpic.nhtsa.dot.gov/api/vehicles/decodevinextended/3GTEK13Y87G527460?format=json): This is an official government VIN search for vehicle make/model details. The output is very detailed, and below is a portion.

"Message": "Results returned successfully",
"SearchCriteria": "VIN:3GTEK13Y87G527460",
"Value": "GENERAL MOTORS LLC",
"Value": "Sierra",
"Value": "2007",
"Value": "1500 (1/2 ton)",
"Value": "TRUCK ",

FAXVIN (https://www.faxvin.com/): This alternative option allows you to enter a VIN to identify full details about the vehicle (but no owner information).

Vehicle History (https://www.vehiclehistory.com/): Vehicle search by VIN which provides details about the make/model/recalls/thefts/etc.

O'Reilly License (https://www.oreillyauto.com/): This option allows you to enter a VIN or license plate to identify full details about the vehicle (but no owner information).

Carvana (https://www.carvana.com): This alternative option allows you to enter a VIN or license plate to identify full details about the vehicle (but no owner information).

 

Facebook Live (https://www.facebook.com/search/str/Live/videos-live): A less powerful replacement for the Facebook Live Video Map, which was eliminated earlier this year.

Facebook Intersect Search Tool (https://www.osintcombine.com/facebook-intersect-search-tool): Graphical option for Facebook intersect searching.

 

Carbon Dating The Web (http://carbondate.cs.odu.edu): This service uses public archives of a domain to estimate the creation date. The following demo of my own site was only off by two months.


DomainBigData ( https://domainbigdata.com): This is a typical Whois lookup site, but contains a free historic record, as seen below. This can identify the owner of a website which currently possesses a private registration.

URLScan (https://urlscan.io/): This resource provides an additional screen capture of the target address, which is often dated prior to undesired website changes or deletions. This is a small supplement to archive sites.

 

Website Informer (https://website.informer.com):This offers yet another unique historical view of a domain.

 

DomainIQ - Hosting Research (https://www.domainiq.com/hosting_research): The screen capture archive of this resource has been extremely helpful in the past. It is currently down, but will hopefully return. When working, the following screen would be full of archived screen captures of a website.

 

FluidDATA Podcast Search Engine (https://fluiddata.com): This resource allows you to search the spoken text of many podcasts. Useful for searching email addresses such as mike at gmail dot com.

BitcoinAbuse (https://www.bitcoinabuse.com): This Bitcoin service identifies incidents of malicious use of cryptocurrencies. Great for tracking the use of Bitcoin in email scams.

 

Google: This Google Search operator will find practically any type of file publicly linked, using the word Book as an example.

 

AIOSearch (http://www.aiosearch.com): This service searches the most popular file sharing hosts.

 

The following three background removal services will attempt to remove any undesired content from an image. This can lead to better results when conducting a reverse image search in attempts to identify a person or object.

Remove.bg (https://www.remove.bg/)
Clipping Magic (https://clippingmagic.com/)
Background Burner (https://burner.bonanza.com/)

The Privacy, Security, & OSINT Show – Episode 118

EPISODE 118-How Neighborhood Watch Watches You

This week I call a company which provides neighborhoods with license plate readers, plus a new email breach notification API in the OSINT segment.


SHOW NOTES:

INTRO:

New (Cheaper) Silent Pocket Faraday Bags:
https://silent-pocket.com/discount/IntelTechniques

Webinar now offline

HOW NEIGHBORHOOD WATCH WATCHES YOU:

Discussion & Call

OSINT:

https://portal.spycloud.com/endpoint/enriched-stats/[email protected]


Data Removal Workbook:
https://inteltechniques.com/data/workbook.pdf

Affiliate Links:

PIA: https://privateinternetaccess.com/pages/buy-vpn/crimeinfo
Amazon: http://amzn.to/2IAyNzm
Silent Pocket: https://silent-pocket.com/discount/IntelTechniques